Distributed denial of service protection management
Abstract
Methods and systems for distributed denial of service (DDoS) protection management are described. The system may aggregate, from a web application firewall (WAF) bridge service that interfaces with one or more WAF services, one or more DDoS event records associated with one or more DDoS events. The system may analyze the one or more DDoS event records via an analysis of one or more headers and one or more payloads of the one or more DDoS event records, logging information, and a threat intelligence feed. The system may generate a security configuration that indicates one or more parameters of the one or more WAF services to be set. The system may validate the security configuration and may transmit the security configuration to the one or more WAF services based at least in part on the validation.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for data processing, comprising:
aggregating, from a web application firewall (WAF) bridge service that interfaces with one or more WAF services, one or more distributed denial of service (DDoS) event records associated with one or more DDoS events, the one or more DDoS event records converted into a common format via generative artificial intelligence (AI) model processing; analyzing the one or more DDoS event records via a first sub-analysis of one or more headers of the one or more DDoS event records and one or more payloads of the one or more DDoS event records, a second sub-analysis of logging information received from the one or more WAF services, and a third sub-analysis of a threat intelligence feed to determine one or more characteristics of the one or more DDoS events; generating, based at least in part on analyzing the one or more DDoS event records, a security configuration for the one or more WAF services that indicates one or more parameters of the one or more WAF services to be set based at least in part on the one or more characteristics of the one or more DDoS events; validating the security configuration in a sandbox environment; and transmitting the security configuration to the one or more WAF services based at least in part on the validation.
2 . The method of claim 1 , wherein performing the first sub-analysis comprises:
transmitting the one or more headers, the one or more payloads, or both, to a generative AI model; and receiving an output of the generative AI model that indicates the one or more characteristics, the output based at least in part on the one or more headers, the one or more payloads, or both.
3 . The method of claim 1 , further comprising:
generating, based at least in part on the one or more characteristics of the one or more DDoS events, a plurality of payloads that are responsive to the one or more DDoS events and that comprise waste data; and transmitting the plurality of payloads to one or more sources of the one or more DDoS events in accordance with a randomized transmission pattern.
4 . The method of claim 1 , further comprising:
deploying a configuration agent and a logging agent that are associated with the one or more WAF services, wherein transmitting the security configuration comprises transmitting the security configuration to the configuration agent, and wherein the logging information is received from the logging agent.
5 . The method of claim 1 , further comprising:
converting the logging information into a structured format; transmitting the converted logging information to a generative AI model; and receiving an output of the generative AI model that indicates the one or more characteristics, the output based at least in part on the converted logging information.
6 . The method of claim 1 , further comprising:
receiving, via a communication channel of a multi-tenant communication service, a request for information associated with the one or more DDoS events, the security configuration, the validation of the security configuration, the one or more WAF services, an analysis of the one or more DDoS event records, or any combination thereof; transmitting, to a generative AI model, a prompt that is based at least in part on the request; receiving an output of the generative AI model that indicates the information; and transmitting a response to the request that is based at least in part on the output of the generative AI model.
7 . The method of claim 1 , further comprising:
generating reporting information associated with the one or more DDoS events, the security configuration, the validation of the security configuration, the one or more WAF services, an analysis of the one or more DDoS event records, or any combination thereof, wherein the reporting information is formatted using a generative AI model.
8 . The method of claim 1 , further comprising:
generating a prediction of one or more future DDoS events based at least in part on the one or more characteristics of the one or more DDoS event records; wherein the security configuration is based at least in part on the prediction.
9 . The method of claim 1 , wherein performing the third sub-analysis comprises:
receiving one or more threat intelligence feed records via the threat intelligence feed; wherein the security configuration is based at least in part on a generative AI analysis of the one or more threat intelligence feed records.
10 . The method of claim 1 , wherein generating the security configuration comprises:
transmitting a prompt to a generative AI model that indicates the one or more characteristics and comprises an instruction to generate the security configuration; and receiving an output of the generative AI model that indicates at least a portion of the security configuration.
11 . The method of claim 1 , wherein the one or more characteristics comprise a quantity of the one or more DDoS events, one or more sources of the one or more DDoS events, one or more actions performed during a time period associated with the one or more DDoS events, or any combination thereof.
12 . The method of claim 1 , further comprising:
performing a risk assessment of the one or more DDoS events based at least in part on the one or more DDoS event records, the logging information, information associated with the threat intelligence feed, previous DDoS event information, or any combination thereof; and determining one or more threat mitigation actions based at least in part on the risk assessment, wherein the security configuration is based at least in part on the risk assessment, the one or more threat mitigation actions, or any combination thereof.
13 . The method of claim 1 , further comprising:
generating one or more security policies, one or more DDoS signatures, or any combination thereof based at least in part on the one or more DDoS event records, the logging information, or any combination thereof.
14 . The method of claim 1 , further comprising:
transmitting mitigation information to an external orchestration service, the mitigation information comprising one or more elements of the one or more DDoS event records, one or more elements of an analysis of the DDoS event records, one or more mitigation operations performed, or any combination thereof; and receiving, from the external orchestration service, mitigation workflow information that is based at least in part on the mitigation information.
15 . An apparatus for data processing, comprising:
one or more memories storing processor-executable code; and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:
aggregate, from a web application firewall (WAF) bridge service that interfaces with one or more WAF services, one or more distributed denial of service (DDoS) event records associated with one or more DDoS events, the one or more DDoS event records converted into a common format via generative artificial intelligence (AI) model processing;
analyze the one or more DDoS event records via a first sub-analysis of one or more headers of the one or more DDoS event records and one or more payloads of the one or more DDoS event records, a second sub-analysis of logging information received from the one or more WAF services, and a third sub-analysis of a threat intelligence feed to determine one or more characteristics of the one or more DDoS events;
generate, based at least in part on analyzing the one or more DDoS event records, a security configuration for the one or more WAF services that indicates one or more parameters of the one or more WAF services to be set based at least in part on the one or more characteristics of the one or more DDoS events;
validate the security configuration in a sandbox environment; and
transmit the security configuration to the one or more WAF services based at least in part on the validation.
16 . The apparatus of claim 15 , wherein, to perform the first sub-analysis, the one or more processors are individually or collectively operable to execute the code to cause the apparatus to:
transmit the one or more headers, the one or more payloads, or both, to a generative AI model; and receive an output of the generative AI model that indicates the one or more characteristics, the output based at least in part on the one or more headers, the one or more payloads, or both.
17 . The apparatus of claim 15 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:
generate, based at least in part on the one or more characteristics of the one or more DDoS events, a plurality of payloads that are responsive to the one or more DDoS events and that comprise waste data; and transmit the plurality of payloads to one or more sources of the one or more DDoS events in accordance with a randomized transmission pattern.
18 . The apparatus of claim 15 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:
deploy a configuration agent and a logging agent that are associated with the one or more WAF services, wherein transmitting the security configuration comprises transmitting the security configuration to the configuration agent, and wherein the logging information is received from the logging agent.
19 . The apparatus of claim 15 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:
convert the logging information into a structured format; transmit the converted logging information to a generative AI model; and receive an output of the generative AI model that indicates the one or more characteristics, the output based at least in part on the converted logging information.
20 . A non-transitory computer-readable medium storing code for data processing, the code comprising instructions executable by one or more processors to:
aggregate, from a web application firewall (WAF) bridge service that interfaces with one or more WAF services, one or more distributed denial of service (DDoS) event records associated with one or more DDoS events, the one or more DDoS event records converted into a common format via generative artificial intelligence (AI) model processing; analyze the one or more DDoS event records via a first sub-analysis of one or more headers of the one or more DDoS event records and one or more payloads of the one or more DDoS event records, a second sub-analysis of logging information received from the one or more WAF services, and a third sub-analysis of a threat intelligence feed to determine one or more characteristics of the one or more DDoS events; generate, based at least in part on analyzing the one or more DDoS event records, a security configuration for the one or more WAF services that indicates one or more parameters of the one or more WAF services to be set based at least in part on the one or more characteristics of the one or more DDoS events; validate the security configuration in a sandbox environment; and transmit the security configuration to the one or more WAF services based at least in part on the validation.Join the waitlist — get patent alerts
Track US2025016194A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.